Alpine: drupal7: security update to 7.91-r0

high Tenable Self-Hosted Container Security Plugin ID 427127

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules possess an authentication
and authorization bypass vulnerability. An attacker with access to a HTTP-request intercepting method is
able to bypass authentication and authorization by removing the SAML Assertion Signature - impersonating
existing users and existing roles, including administrative users/roles. This vulnerability is not
mitigated by configuring the module to enforce signatures or certificate checks. Xecurify recommends
updating miniOrange modules to their most recent versions. This vulnerability is present in paid versions
of the miniOrange Drupal SAML SP product affecting Drupal 7, 8, and 9. (CVE-2022-26493)

See Also

https://security.alpinelinux.org/vuln/CVE-2022-26493

Plugin Details

Severity: High

ID: 427127

Version: Revision 1.4

Type: Local

Published: 5/16/2025

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2022-26493

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/3/2022

Reference Information

CVE: CVE-2022-26493